CVE-2025-21238
Published: 14 January 2025
Description
Windows Telephony Service Remote Code Execution Vulnerability
Security Summary
CVE-2025-21238 is a Remote Code Execution vulnerability affecting the Windows Telephony Service. Published on 2025-01-14, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-122 and NVD-CWE-noinfo.
The vulnerability enables remote exploitation over the network with low attack complexity and no required privileges, though it necessitates user interaction. A successful attack allows an unauthenticated attacker to achieve high impacts on confidentiality, integrity, and availability, resulting in remote code execution on the targeted system.
Microsoft's update guide provides details on mitigation and patching for this vulnerability at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21238.
Details
- CWE(s)